Business
Individual
Partners
Intelligence
How we work
Sign in Check my firm
Glossary › Patterns › Email authentication
Reference · Pattern

DKIM signing absent on the primary mail sender

Severity MediumKind Email authenticationEffort to fix ModerateUpdated 29 Sep 2026By LeakTrace
Definition

A domain's outbound mail is not cryptographically signed, so receivers cannot verify integrity or authenticity beyond IP-based SPF.

What it is

DKIM (DomainKeys Identified Mail) attaches a cryptographic signature to outbound mail that receivers verify against a public key published in DNS. Without DKIM, DMARC alignment can only rely on SPF, which fails on legitimate forwarded mail and gets brittle under any mail-flow change (new marketing platform, new e-sign vendor, forwarded newsletters).

Why it matters

Attackers rarely attack DKIM directly, they attack its absence. A domain with SPF-only alignment produces intermittent DMARC failures on legitimate mail, which pressures the domain owner to set p=none and keep it there. That permissive posture is what the attacker actually wants.

How anyone can check it

Send yourself an email and view its headers. Look for dkim=pass and your own domain after d=.

Remediation direction

Enable DKIM signing on every legitimate sender (Google Workspace, Microsoft 365, marketing platform, ATS, e-sign vendor) with 2048-bit keys. Publish each selector at <selector>._domainkey.<domain>. Verify with a DMARC aggregate report review after two weeks.

LeakTrace does not perform the fix. In an assessment, every finding carries a step-by-step remediation for the firm’s IT provider.

See what is open from outside before anyone else does. Check my firm →